CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
- Affected products
- Apache Tika
- Apache Tika
- < 1.18
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 91.1% (100th percentile)
- NVD status
- Modified
- Published
- 2018-04-25
CVE-2018-1335 at NVD
15 known exploits for CVE-2018-1335
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2018-1335
CVE-2018-1335-EXP-GUI
CVE-2018-1335-Python3
CVEs
CVE-2018-1335
cve-2018-1335
Exploit for Code Injection in Pivotal_Software Spring_Data_Commons
Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)
Apache Tika 1.15 - 1.17 - Header Command Injection Exploit
Apache Tika 1.17 Header Command Injection
Apache Tika-server 1.18 - Command Injection
Apache Tika-server < 1.18 - Command Injection
Apache Tika Server Command Injection
Apache Tika-server < 1.18 - Command Injection Exploit
Apache Tika Header Command Injection